CVE-2026-68150: fs/super: fix emergency thaw double-unlock of s_umount

Published Aug 10, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

fs/super: fix emergency thaw double-unlock of sumount

dothawall() iterates over all superblocks via iteratesupers() with SUPERITEREXCL, which acquires sumount exclusively before calling the callback and releases it afterwards. However, the callback dothawallcallback() calls thawsuperlocked() which unconditionally releases sumount on every code path. This results in a second unlock attempt in iteratesupers() that corrupts the rwsem state, triggering a DEBUGRWSEMS warning:

[ 182.601148] sysrq: Emergency Thaw of all frozen filesystems [ 182.601865] ------------[ cut here ]------------ [ 182.602375] DEBUGRWSEMSWARNON((rwsemowner(sem) != current) && !rwsemtestoflags(sem, RWSEMNONSPINNABLE)): count = 0x0, magic = 0xffff99b1011e5870, owner = 0x0, curr 0xffff99b101b06c80, list not empty [ 182.603817] WARNING: kernel/locking/rwsem.c:1412 at upwrite+0xa3/0x170, CPU#2: kworker/2:1/53 [ 182.604578] Modules linked in: [ 182.604864] CPU: 2 UID: 0 PID: 53 Comm: kworker/2:1 Not tainted 7.2.0-rc4-00001-gbd3bd93ea98a-dirty #4 PREEMPT(lazy) [ 182.605711] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.13.0-1kylin1 04/01/2014 [ 182.606417] Workqueue: events dothawall [ 182.606750] RIP: 0010:upwrite+0xaf/0x170 [ 182.607076] Code: 19 3a 92 48 0f 44 c2 48 8b 55 08 48 8b 55 00 4c 8b 45 08 48 8b 55 00 48 8d 3d ad 91 e0 01 48 8b 4d 20 50 48 c7 c6 f0 8c 26 92 <67> 48 0f b9 3a e8 d7 93 4e 00 58 eb 81 48 83 7f 18 00 48 c7 c2 8d [ 182.608563] RSP: 0018:ffffb670001d7e08 EFLAGS: 00010246 [ 182.609007] RAX: ffffffff92349e8d RBX: 0000000000000000 RCX: ffff99b1011e5870 [ 182.609595] RDX: 0000000000000000 RSI: ffffffff92268cf0 RDI: ffffffff92914d10 [ 182.610283] RBP: ffff99b1011e5870 R08: 0000000000000000 R09: ffff99b101b06c80 [ 182.610847] R10: ffff99b10139a808 R11: fefefefefefefeff R12: 0000000000000000 [ 182.611414] R13: ffffffff90cf74d0 R14: 0000000000000000 R15: ffff99b1011e5800 [ 182.612009] FS: 0000000000000000(0000) GS:ffff99b1eaaee000(0000) knlGS:0000000000000000 [ 182.612670] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 182.613146] CR2: 00000000005c631c CR3: 00000000013ee000 CR4: 00000000000006f0 [ 182.613722] Call Trace: [ 182.613946] <TASK> [ 182.614130] iteratesupers+0x128/0x150 [ 182.614463] dothawall+0x1b/0x30 [ 182.614759] processscheduledworks+0xbb/0x3f0 [ 182.615150] ? pfxworkerthread+0x10/0x10 [ 182.615499] workerthread+0x129/0x270 [ 182.615816] ? pfxworkerthread+0x10/0x10 [ 182.616201] kthread+0xe2/0x120 [ 182.616469] ? pfxkthread+0x10/0x10 [ 182.616792] retfromfork+0x15b/0x240 [ 182.617115] ? pfxkthread+0x10/0x10 [ 182.617426] retfromforkasm+0x1a/0x30 [ 182.617761] </TASK> [ 182.617968] ---[ end trace 0000000000000000 ]--- [ 182.618412] Emergency Thaw complete

Fix this by switching to SUPERITERUNLOCKED and acquiring sumount in the callback via superlockexcl() before calling thawsuperlocked(). This matches the locking pattern expected by thawsuperlocked() and eliminates the double unlock.

While at it, remove the dead 'return;' at the end of dothawallcallback().

Affected Software

1 affected component
Linux Linux kernel

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Linux kernel to a version that resolves this vulnerability.

    Fixed in 7.2.0-rc4-00001-gbd3bd93ea98a-dirty
  2. Configuration

    In fs/super, adjust the emergency-thaw iteration to use SUPER_ITER_EXCL (exclusive s_umount acquisition). This matches the locking pattern expected by the thaw callback and prevents the double-unlock/corruption of rwsem state that triggers DEBUG_RWSEMS_WARN_ON.

    Linux kernel (fs/super) SUPER_ITER_EXCL / SUPER_ITER_UNLOCKED = use SUPER_ITER_EXCL (acquire s_umount exclusively before iterating)
  3. Configuration

    In the fs/super emergency thaw implementation, ensure thaw_super_locked() is used to handle the unlocking so that s_umount is not double-unlocked in a second unlock attempt in __iterate_supers(); eliminate the dead/incorrect unlock that leads to corrupted rwsem state and the warning in kernel/locking/rwsem.c (up_write).

    Linux kernel (fs/super) thaw_super_locked() / double-unlock behavior = remove the second unlock path and make thaw_super_locked() unconditionally release s_umount on every code path

Event History

Aug 10, 2026
CVE Published
via MITRE·11:59 AM
Data Sourced
via MITRE·11:59 AM
Description
Data Sourced
via NVD·01:20 PM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-68150?

The severity of CVE-2026-68150 is rated as 22.

2

What does CVE-2026-68150 affect?

CVE-2026-68150 affects the Linux kernel, specifically related to the emergency thaw operation of superblocks.

3

How does CVE-2026-68150 impact Linux kernel security?

CVE-2026-68150 can lead to a potential double-unlock scenario in the handling of superblocks, which may affect system stability.

4

How do I fix CVE-2026-68150?

To fix CVE-2026-68150, ensure that you apply the latest patches provided for the Linux kernel.

5

When was CVE-2026-68150 published?

CVE-2026-68150 was published on August 10, 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203